CVE-2025-14612
Insecure Temporary File in Altera Quartus Prime Pro Installer
Publication date: 2026-01-07
Last updated on: 2026-01-07
Assigner: Altera
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| altera | quartus_prime_pro | From 24.1 (inc) to 25.1.1 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-377 | Creating and using insecure temporary files can leave application and system data vulnerable to attack. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Insecure Temporary File issue in the Altera Quartus Prime Pro Installer (SFX) on Windows. It involves the use of predictable file names for temporary files, which can lead to security risks. The affected versions are Quartus Prime Pro from 24.1 through 25.1.1.
How can this vulnerability impact me? :
The use of predictable temporary file names can allow an attacker with limited privileges to potentially interfere with the installation process or access sensitive information by exploiting these predictable file paths. This can lead to unauthorized information disclosure, modification, or denial of service during installation.